Potential OGNL Injection Exploitation In JVM Based Application

 Original Source: [Sigma source]
Title: Potential OGNL Injection Exploitation In JVM Based Application
Status: test
Description:Detects potential OGNL Injection exploitation, which may lead to RCE. OGNL is an expression language that is supported in many JVM based systems. OGNL Injection is the reason for some high profile RCE's such as Apache Struts (CVE-2017-5638) and Confluence (CVE-2022-26134)
References:
  -https://www.wix.engineering/post/threat-and-vulnerability-hunting-with-application-server-error-logs
Author: Moti Harmats
Date: 2023-02-11
modified:None
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
  • -'cve.2017-5638'
  • -'cve.2022-26134'
Logsource:
  • category: application
  • product: jvm
  • definition: Requirements: application error logs must be collected (with LOG_LEVEL=ERROR and above)
Detection:
  keywords:
    - 'org.apache.commons.ognl.OgnlException'
    - 'ExpressionSyntaxException'
  condition:keywords
Falsepositives:
  -Application bugs
Level: high